IOC Report
z3hir.x86.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/z3hir.x86.elf
/tmp/z3hir.x86.elf
/tmp/z3hir.x86.elf
-
/tmp/z3hir.x86.elf
-
/tmp/z3hir.x86.elf
-
/tmp/z3hir.x86.elf
-
/tmp/z3hir.x86.elf
-
/tmp/z3hir.x86.elf
-

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
170.60.138.128
unknown
Switzerland
162.234.58.31
unknown
United States
211.138.224.49
unknown
China
83.128.255.83
unknown
Netherlands
45.52.254.169
unknown
United States
212.45.199.115
unknown
Switzerland
62.135.4.22
unknown
Egypt
184.125.201.144
unknown
United States
109.176.44.233
unknown
United Kingdom
254.24.41.120
unknown
Reserved
139.167.58.99
unknown
India
31.251.222.217
unknown
Germany
180.101.40.199
unknown
China
185.170.187.134
unknown
Moldova Republic of
162.62.116.230
unknown
Singapore
89.210.54.37
unknown
Greece
116.24.218.40
unknown
China
216.121.100.91
unknown
United States
217.142.13.109
unknown
Sweden
219.215.7.178
unknown
Japan
171.88.238.0
unknown
China
38.188.164.222
unknown
United States
16.100.173.142
unknown
United States
171.211.236.100
unknown
China
243.159.42.203
unknown
Reserved
67.231.218.144
unknown
Canada
155.42.184.38
unknown
United States
69.226.230.83
unknown
United States
200.254.246.18
unknown
Brazil
221.220.146.225
unknown
China
4.155.55.137
unknown
United States
17.186.70.25
unknown
United States
246.12.137.156
unknown
Reserved
77.197.50.101
unknown
France
107.145.254.225
unknown
United States
82.82.11.154
unknown
Germany
109.249.104.224
unknown
United Kingdom
83.133.136.163
unknown
European Union
209.138.97.243
unknown
United States
85.134.74.16
unknown
Finland
222.154.100.55
unknown
New Zealand
221.146.25.133
unknown
Korea Republic of
213.253.113.107
unknown
Slovenia
100.183.96.97
unknown
United States
240.34.20.106
unknown
Reserved
245.20.147.103
unknown
Reserved
125.13.82.121
unknown
Japan
125.222.69.255
unknown
China
35.225.224.176
unknown
United States
122.131.173.254
unknown
Japan
65.125.42.118
unknown
United States
252.243.88.78
unknown
Reserved
153.0.146.185
unknown
China
59.219.211.114
unknown
China
123.58.253.58
unknown
China
97.167.234.101
unknown
United States
44.172.145.8
unknown
United States
106.136.29.181
unknown
Japan
219.14.134.165
unknown
Japan
112.157.123.241
unknown
Korea Republic of
5.74.168.46
unknown
Iran (ISLAMIC Republic Of)
36.70.64.16
unknown
Indonesia
200.38.113.203
unknown
Mexico
178.157.241.143
unknown
Denmark
244.172.65.87
unknown
Reserved
81.78.98.137
unknown
United Kingdom
90.217.222.103
unknown
United Kingdom
218.71.178.40
unknown
China
68.11.0.104
unknown
United States
91.92.231.144
unknown
Iran (ISLAMIC Republic Of)
145.79.46.249
unknown
Netherlands
166.94.19.6
unknown
United States
58.58.153.14
unknown
China
178.57.0.23
unknown
Russian Federation
248.238.201.227
unknown
Reserved
160.130.184.42
unknown
United States
168.38.212.109
unknown
United States
162.101.183.252
unknown
United States
176.91.64.129
unknown
Turkey
61.21.29.90
unknown
Japan
250.65.26.37
unknown
Reserved
101.85.152.84
unknown
China
115.194.192.14
unknown
China
81.112.8.76
unknown
Italy
27.55.110.71
unknown
Thailand
184.224.70.229
unknown
United States
213.181.28.237
unknown
Russian Federation
97.225.123.149
unknown
United States
16.116.57.60
unknown
United States
59.126.125.204
unknown
Taiwan; Republic of China (ROC)
222.160.76.159
unknown
China
175.137.126.156
unknown
Malaysia
79.116.103.93
unknown
Romania
222.191.78.44
unknown
China
8.116.114.179
unknown
United States
48.3.58.78
unknown
United States
88.224.86.0
unknown
Turkey
1.126.170.132
unknown
Australia
202.69.75.92
unknown
Hong Kong
150.81.196.155
unknown
Japan
There are 90 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
8058000
page execute read
malicious
8058000
page execute read
malicious
8058000
page execute read
malicious
c02000
page execute read
f7f6d000
page execute read
c02000
page execute read
91c3000
page read and write
f7f6d000
page execute read
f7f6d000
page execute read
c02000
page execute read
91c3000
page read and write
91c3000
page read and write
8059000
page read and write
ff9c9000
page read and write
8059000
page read and write
ff9c9000
page read and write
8059000
page read and write
ff9c9000
page read and write
There are 8 hidden memdumps, click here to show them.